CVE-2026-1555 affects the WebStack theme for WordPress. In all versions up to and including 1.2024, the io_img_upload() function does not properly validate uploaded file types, allowing arbitrary file upload. Because the vulnerable upload functionality can be reached without authentication, an unauthenticated attacker can submit crafted files to the server. If the uploaded file is placed in a web-accessible location and executable by the server-side environment, this can lead to remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
The repository contains one standalone Python script, CVE-2026-1555.py. It is a threaded multi-target WordPress upload exploit rather than a detection utility. Targets are supplied with -u/--url or read from list.txt, normalized to HTTP(S), and processed concurrently. For each target, the script POSTs a multipart request to /wp-admin/admin-ajax.php with action=img_upload and an operator-selected file in the files field. It disables TLS certificate verification and proxy use, uses a browser-like User-Agent, and waits up to 15 seconds per request. A target is considered successfully exploited only when the response is JSON with status: 1 and data.src; the returned URL is saved to uploaded_paths.txt. The script does not include an actual shell or other payload, but its default payload name (shell.php) and output wording indicate intended use for uploading a PHP web shell. It relies entirely on a vulnerable/misconfigured WordPress img_upload handler that allows arbitrary file uploads and returns a public file URL.
Small exploit repository centered on a single operational payload, `ms.php`, plus documentation and discovery artifacts. The README describes a GUI-based exploit tool for CVE-2026-1555 against the WebStack WordPress theme, but that Python entrypoint is not present in the provided repository snapshot; the only actual exploit code included is the PHP payload. `ms.php` is a password-protected multipurpose webshell intended to be uploaded through the claimed unauthenticated file upload flaw and then accessed over the web. It supports authenticated session handling, command execution using several PHP functions (`shell_exec`, `exec`, `system`, `passthru`, `popen`) and Windows COM (`WScript.shell`), file read/write/delete, file upload, directory browsing, system information gathering, WordPress configuration discovery, extraction of DB credentials from `wp-config.php`, manual MySQL command execution, and reverse shell assistance. The repository also includes `Dork.txt` with a fingerprinting string for locating likely WebStack theme deployments and `requirements.txt` listing dependencies for the missing GUI tool. Overall, this is a real exploit-related repository with an operational post-exploitation payload rather than a mere detector; however, the initial upload exploit implementation itself is absent from the analyzed files, so the repository as provided mainly delivers the webshell component and usage guidance rather than the full end-to-end exploitation code.
Repository contains a single Python exploit script, a README, and a license file. The main script CVE-2026-1555.py is a multithreaded bulk exploitation tool targeting CVE-2026-1555, described as an unauthenticated arbitrary file upload in the WebStack WordPress theme up to version 1.2024. The exploit reads target base URLs from a file, normalizes them to HTTP/HTTPS, and for each target sends a multipart POST request to /wp-admin/admin-ajax.php with action=img_upload and an operator-selected local file. It expects a JSON response containing status=1 and data.src, which it treats as the uploaded file URL. Successful URLs are printed and appended to uploaded_paths.txt. The script disables TLS verification warnings, sets NO_PROXY=*, uses a browser-like User-Agent, and supports configurable worker threads. This is a real exploit rather than a detector: its core capability is arbitrary file upload, and the documented intended outcome is remote code execution by uploading a PHP webshell and then invoking it directly via the returned URL.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.